Security researchers warn Apple that “AirTag” could be a “good Samaritan attack”

The loss prevention tag “AirTag” announced by Apple in April could be used for phishing scams. “Krebs on Security,” run by security journalist Brian Krebs, warned on September 28 (local time).

 airtag 1 AirTag is 3800 yen per piece

If AirTag is set to “lost mode”, a unique URL for https://found.apple.com will be generated and you own the AirTag there. Allows a person to enter a contact’s phone number or email address.

Krebs warns that this feature could be used to redirect “Good Samaritan” to iCloud phishing pages or other malicious websites. bottom. (A good Samaritan is the Samaritan who helped a lost traveler in the Gospel of Luke 10: 25-37.)

) For example, if a person who finds an AirTag of a lost item scans the AirTag, it will be automatically transferred to the URL.

However, since it is possible to enter any code other than the phone number and email address in the lost mode, for example, the person who scanned the AirTag You may be redirected to a fake iCloud login page or another malicious site.

It’s possible that something other than your phone number or email address is entered on found.apple.com

Security consultant Bobby Rauff explained the issue to Krebs on Security. Rauff reported the issue to Apple on June 20, but Apple hasn’t addressed the issue yet. He told Krebs on Security that he had given him 90 days to open the issue to the public.

“I can’t remember other cases where these low-cost small tracking devices could be weaponized” (Rauf)

The price of one AirTag is $ 29 (3800 yen in Japan).

Mr. Krebs introduced a scenario that actually happened in the past and abused an inexpensive USB drive. An attacker drops a malware-laden USB in the parking lot of a company he wants to hack, and employees think it’s a lost item and connect it to an office PC to break into the network. This actually happened in 2008 in a parking lot at a US Department of Defense facility.

Rauff said the issue may not be the most important issue for Apple, but it should be easy to fix. Apple hasn’t responded to Krebs on Security’s request for comment.

Copyright © ITmedia, Inc. All Rights Reserved.

Note: This article have been indexed to our site. We do not claim ownership or copyright of any of the content above. To see the article at original source

Click Here

Related Posts
Piers Morgan responds to replacing Phillip Schofield on This Morning thumbnail

Piers Morgan responds to replacing Phillip Schofield on This Morning

Piers Morgan has spoken out on how he feels about possibly replacing Phillip Schofield on This Morning.After more than two decades on the air, Schofield announced his departure from the long-running ITV morning show in a surprise statement shared on Saturday (20 May).Piers Morgan posted this picture of himself with remaining This Morning presenter Holly
Read More
PS5 vs PS4 Sales Comparison in Europe thumbnail

PS5 vs PS4 Sales Comparison in Europe

PS5 vs PS4 Sales Comparison in Europe - October 2023 - Sales by William D'Angelo , posted 3 days ago / 3,456 ViewsThe VGChartz sales comparison series of articles are updated monthly and each one focuses on a different sales comparison using our estimated video game hardware figures. The charts include comparisons between the PlayStation
Read More
Monkey Bread by Akis Petretzikis thumbnail

Monkey Bread by Akis Petretzikis

Monkey Bread από τον Άκη Πετρετζίκη. Φτιάξτε τα πιο νόστιμα και αφράτα ψωμάκια τα οποία μπορείτε να βουτήξετε μέσα σε λιωμένη σοκολάτα!
Read More
Index Of News
Total
0
Share